🇺🇸
Ben Schoolland
2026-09-11 11:08:51
(1 day ago)
Requested known WordPress backdoor/scanner-only paths. No legitimate use.
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-11 05:42:00
(2 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇩🇪
Goetz
2026-09-03 09:43:34
(1 week ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇫🇷
Sklurk
2026-08-03 03:11:08
(1 month ago)
Web App Attack
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=26; exact paths: /xmlrpc.php
Web App Attack
Anonymous
2026-07-23 06:36:33
(1 month ago)
WordPress Brute Force
Brute-Force
🇩🇪
stinpriza
2026-07-12 05:16:40
(2 months ago)
Web App Attack
Web App Attack
🇩🇪
Lino Project
2026-02-18 03:33:38
(6 months ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
🇺🇸
TPI-Abuse
2026-02-18 00:47:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 19:47:16.377489 2026] [security2:error] [pid 32360:tid 32360] [client 65.111.1.34:19739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pattymoorearmstrong.com"] [uri "/app/.env"] [unique_id "aZUMFDw6CE-3Ufy1iuCZeAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2025-12-13 22:02:38
(8 months ago)
2025-12-13 @ 23:02:37 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 14:52:11
(9 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
🇺🇸
TPI-Abuse
2025-11-24 08:33:27
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:33:22.606963 2025] [security2:error] [pid 24359:tid 24359] [client 65.111.1.34:18995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bccoa.net"] [uri "/.git/HEAD"] [unique_id "aSQYUuHLwZv9Ntb2wsmEfwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:56:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:56:45.586413 2025] [security2:error] [pid 26443:tid 26443] [client 65.111.1.34:29347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weismanovens.daveweisman.com"] [uri "/.git/HEAD"] [unique_id "aSQBrXgPFja1bAfJRKO4YQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:22:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:22:15.525446 2025] [security2:error] [pid 23177:tid 23177] [client 65.111.1.34:50641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.royal-barbershop.com"] [uri "/.git/HEAD"] [unique_id "aSP5ly8XRplgMx0iAWy1KgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:37:56
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:37:43.005511 2025] [security2:error] [pid 3299407:tid 3299407] [client 65.111.1.34:58607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmersmutualcallaway.com"] [uri "/.env"] [unique_id "aSPhF4IXAwPsu5LahSUZdQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack